forked from w3c/webauthn
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Inline and clarify the "Relaxing the Same-Origin Restriction" algorithm
Issue w3c#256 notes that it is "not clear whether [we] actually want the interaction with sandboxing that the document.domain setter has", nor "whether [we] actually want the behavior to be affected by previous `document.domain` sets". This patch offers a way to fix that, by: 1) Extracting the procedure from HTML51 into a forked algorithm 2) Adjusting said algorithm to operate on a Document's "original Domain" so as to be independent of previous `document.domain` set operations. 3) Keeping the sandboxing interactions, though I'm not entirely versed in whether there are problematic corner cases here. This spec necessarily adds normative reference to the PSL (which was transitively referenced via normative reference from HTML51 before), and also to the URL specification (also previously transitive from HTML51).
- Loading branch information
Showing
1 changed file
with
53 additions
and
8 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters